Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

51–60 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#51
post #3

> The GDPR is seen as one of Europe's most complex pieces of legislation by the technology sector Really? Now I'm no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document ( https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... ) is only 88 pages long, this cannot realistically be "one of Europe's most complex pieces of legislation". A lot of privacy-conscio…

It might be relatively easy to read, but for SMBs it's hard to actually implement in real life, because GDPR and the EU's stance so far often doesn't take economic reality into account. For small businesses, GDPR in many regards created a legal limbo while large corporations scoff at that regulation and have their legal departments deal with it however they see fit.

For instance, there's this tiny, gnarly aspect of where you are allowed to store your customer data.

Hosting data on servers located in the EU isn't required by GDPR in and of itself, as long as you have a valid data processing agreement with the provider stating how and according to which provisions customer data is protected on their machines.

However, according to a 2020 European Court of Justice ruling you're not allowed to transfer any personally identifiable information to companies that are in any way affiliated with a US-based entity (e.g., by virtue of having a US-based parent company) anymore. Just being physically located in the EU isn't sufficient according to this ruling.

The reason for this is that with FISA US law enforcement can force US-based companies to hand over any data, even if that data is stored with an international subsidiary under a completely different jurisdiction.

This basically invalidates all of the provisions and legal frameworks for interacting with non-EU entities that used to be acceptable under GDPR before (e.g., Privacy Shield).

However, not interacting with any US-based or US-related entities at all anymore would be tantamount to ceasing almost all economic activity. So, until (or more pessimistically: unless) the US and the EU come to terms on a new agreement regarding privacy rules, there probably isn't anything a business can do on its own to completely address this issue. At this point, merely hosting data on servers physically located in the EU perhaps amounts to little more than window dressing.

As soon as a business has dealings with a US-based company or an EU-based company owned by a US-based company that potentially might have access to user data that business technically is in violation of GDPR. As of now, as a business you essentially have three alternatives:

1. Run the entire infrastructure you need yourself or have it run by EU-based companies guaranteed to have no relations with US-based entities whatsoever (Good luck with finding those ...). This, for example, includes payment systems and banking infrastructure, because guess where many EU-based banks host their infrastructure? That's right, AWS.

2. Go out of business.

3. Ignore this aspect of GDPR for now, document everything, continue to do your own due diligence, and hope for the best.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#52
post #27

Earlier quoted context omitted.

> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

I spent months implementing GDPR compliance with a set of EU-based lawyers. Most businesses are not actually GDPR compliant, even to this day. I assume this is a big reason the EU is willing to take another look at what is required for compliance.

And what exactly is making it complicated?

I've also helped a bunch of organization become compliant, some were easier than others. The ones that were harder were the ones that generally didn't have good processes with data in the first place, where everything was scattered all over the place and everyone had access to everything. It makes sense to me that it's harder to be compliant if you were borderline malicious with how you treated personal data before GDPR.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#53
post #28

Earlier quoted context omitted.

>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. It doesn't help the situation that a…

If your salary would drop 95% tomorrow if you didn't tell everyone at the office 'I may remember this conversation' every time you see them, what would you do? Non targeted ads pay 90+% less than targeted. Sure it's not 'required', but the vast majority of businesses would fail overnight if their revenue dropped 90%.

They should consider that it's playing against fines of up to 20m EUR or 4% turnover (not income)

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#54

I think the title is clickbait'y. The EU proposes to simplify the law rather than abolish it, which makes sense to me.

And in the world of bureaucracy, "simplification" doesn't mean what you'd think it should mean.

"Simplification" consists in adding exceptions, which are in effect additional rules and special cases.

Simplification actually means everything gets more complex.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#55
post #16

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

Consent for non-essential cookies, like analytics, is required. You must also provide a clear link to your cookie usage policy, and a simple way to opt-out. This notification is not necessary if you only use functional cookies; for example, using a cookie to only show an on-boarding tutorial once is acceptable.

Organizations, and typically lawyers, skew conservative and lazy. A little cookie-consent cottage industry popped up to handle GDPR, so instead of worrying about the regulations most companies pay the small monthly service charge for a third party to handle consent. The consent companies built the most compatible solution, a banner, with the most conservative options as default to prevent any legal quandary.

Most public facing sites do have analytics (usually LOTS of analytics) and ads, so the banner is mandatory for them. If you understand the regulations, and don't violate them, then consent is not necessary.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#56
post #26

Earlier quoted context omitted.

No. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?

How do you interpret this about strictly necessary cookies, from gdpr.eu? > While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.

Just put it on the Privacy Policy page on your website, as many websites do.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#57
post #35

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

The cookie banners don't make companies less "careless"

They just introduce a needless bit of friction in the UX.

If the EU wanted to prevent digital identity triangulation or cross-domain advertising data gathering, it should have banned it outright. Rather than getting all users to click a stupid banner every time they visit a website.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#58
post #26

Earlier quoted context omitted.

No. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?

How do you interpret this about strictly necessary cookies, from gdpr.eu? > While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.

Sure, you pop all that nonsense on the privacy policy page linked at the bottom of your page, down near that "terms of use" nonsense

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#59
post #35

Earlier quoted context omitted.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

They should not be careless, but they can be spared some paperwork as long as they stay compliant with the spirit of regulation.

If you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#60
post #27

Earlier quoted context omitted.

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

No. The reason it exists is businesses get guidance from legislators and existing case law on what prevents you from running a foul of GDPR and the cookie banner is what we ended up with. If those banners did nothing, companies wouldn't include them. They are there as the lowest effort legal defense.
Post reply on HN